Menu
Browse

Cyber Incident Victim: Lifespan Services

Date

Dec 2025

Location

United States of America

Status

Unknown

Updated

2026-08-04 13:02

Timeline
Occurred
Dec 2025
Discovered
Undetermined
Disclosed
Jul 2026
Resolved
Pending
Summary

Lifespan Physicians Group experienced an unauthorized intrusion into its historic server network that exposed the personal information of over 290,000 patients. The compromised data included names, dates of birth, contact details, Social Security numbers, driver’s license numbers, financial account information, and medical records, affecting individuals associated with Hawthorn Medical Associates, Saint Anne’s Hospital, and Morton Hospital. State attorneys general were notified, and affected individuals were informed several months after the intrusion.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 15 and 16 of 2025 an unauthorized actor gained access to Lifespan Physicians Group’s historic server network, compromising systems associated with its affiliated entities Hawthorn Medical Associates, Saint Anne’s Hospital and Morton Hospital. The intrusion remained undisclosed until July 16 2026 when Lifespan notified the Massachusetts Office of the Attorney General and the Vermont Attorney General of the breach. According to the notifications, 290,357 residents of Massachusetts and 86 residents of Vermont were identified as having their personal information exposed. The affected individuals are patients of the aforementioned medical groups that operate under the Brown Health Medical Group‑MA brand. The delay between the breach discovery and public notification spanned approximately seven months, a period noted in the disclosures as potentially violating state and federal reporting requirements. No further technical details about the method of intrusion or the specific servers involved were provided in the public statements.

Cyber Incident Image

The data that may have been compromised includes names, dates of birth, contact information, compensation or payroll details, licensure or credentialing records, medical or disability‑related information, Social Security numbers, driver’s license numbers or other government‑issued identification numbers, credit or debit card numbers and financial account information. Because of the breadth of data exposed, individuals whose information was accessed face an elevated risk of identity theft, financial fraud and other privacy violations as stated in the breach notice. The notice also indicates that affected persons may be entitled to seek monetary damages and to request injunctive relief compelling Lifespan to improve its cybersecurity practices. The breach notice further explains that the compromised information could be used to open fraudulent accounts, obtain unauthorized medical services or manipulate financial records. No evidence of actual misuse of the data has been disclosed in the available reports, and the notifications do not identify the threat actor or attribute the intrusion to any particular group. The incident underscores the challenges faced by healthcare organizations in safeguarding legacy systems that retain historical patient records.

Sources
Sources available to members
1 source